Snapshot 42377
Normalized text
Scripts and page chrome removed; this is what change detection compares.
LocaliQ US Personal Data Processing Addendum Definitions Nature of the Processing Vendor Processing Requirements Company Obligations Rights of Data Subjects Technical and Organizational Safeguards and Information Security Program Audits Personal Data Incident Notifications Privacy Representative Liability Term Governing Law, Jurisdiction and Venue Conformance with Data Protection Laws Conflict SCHEDULE 1 TO US DPA Specific Business Purposes of Processing Schedule 2 TO US DPA LocaliQ US Personal Data Processing Addendum LocaliQ US Personal Data Processing Addendum Definitions Nature of the Processing Vendor Processing Requirements Company Obligations Rights of Data Subjects Technical and Organizational Safeguards and Information Security Program Audits Personal Data Incident Notifications Privacy Representative Liability Term Governing Law, Jurisdiction and Venue Conformance with Data Protection Laws Conflict SCHEDULE 1 TO US DPA Specific Business Purposes of Processing Schedule 2 TO US DPA LocaliQ US Personal Data Processing Addendum This LocaliQ US Personal Data Security and Privacy Addendum (“US DPA”) entered into by and between ReachLocal, Inc. dba LocaliQ, USA TODAY Media Corp. and affiliated entities (each the “Vendor” or “LocaliQ”) and the customer (“Company”) identified on the applicable LocaliQ insertion order or advertising commitment (“Order”), governs the processing of Personal Data of U.S. Data Subjects in connection with LocaliQ digital marketing services (the “Services”). This DPA is incorporated into and forms part of the LocaliQ terms and conditions. Collectively, this DPA, the applicable Order and the LocaliQ terms and conditions are referred to in this DPA as the “Agreement”. This US DPA is intended only for U.S. customers of Vendor and applies only to the Processing of U.S. Company Personal Data. Definitions As used in this US DPA, the following terms shall have the following meanings: “Applicable Laws” means any and all laws, statutes, rules, regulations, and ordinances applicable to a party’s obligations under the Agreement including, without limitation, all applicable Data Protection Laws. “Data Protection Laws” means the federal and state Personal Data protection or privacy laws of the United States of America, including without limitation, (a) the California Consumer Privacy Act of 2018, the (“CCPA”);(b) the Virginia Consumer Data Protection Act, when effective; (c) the Colorado Privacy Act and its implementing regulations, when effective; (d) the Utah Consumer Privacy Act, when effective; and (e) Connecticut SB6, An Act Concerning Personal Data Privacy and Online Monitoring, when effective, as such laws are amended, together with any successor laws and/or regulations. The terms “Business,” “Consumer,“ and “Service Provider” have the same meaning as in the CCPA. The terms “Controller” and “Processor” shall have the same meaning as in VCDPA. “Company Personal Data” means any and all data and information of Company, its affiliates, and/or their respective customers, prospects and end users Processed by Vendor and its Sub-Processors that is also Personal Data, including without limitation any such Personal Data collected, produced or otherwise provided via the Services, and includes login credentials. Company Personal Data is the Confidential Information of Company under the Agreement. “Data Subject” means the identified or identifiable natural person to whom Personal Data relates, including but not limited to a “consumer” or “individual” under the Data Protection Laws. “Information Security Program” an implemented written information security program that includes administrative, technical, and physical safeguards that ensure the confidentiality, integrity, and availability of Personal Data, protects against any reasonably anticipated threats or hazards to the confidentiality, integrity and availability of the Personal Data, and protects against unauthorized access, use, disclosure, alteration or destruction of the Personal Data. “Personal Data” means data or information that identifies, relates to, describes, references, or is reasonably capable of being associated with an identified or identifiable natural person or household (in the case of the CCPA) and/or which may be defined as personally identifying data or information as determined by Applicable Laws from time to time. “Personal Data Incident” means the accidental, unlawful, or unauthorized destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. A Personal Data Incident will not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems. “Process(ed)(ing)” means any operation or set of operations which is performed upon Company Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available. “Service(s)” has the meaning set forth in the Agreement. “Sensitive Personal Data” shall have the meaning under applicable Data Protection Laws. “Sub-Processor” means any subcontractor engaged by Vendor that Processes Personal Data in connection with the Services. Nature of the Processing The categories of Personal Data Processed subject to this DPA are described in Schedule 1. The parties agree that the Processing of Personal Data as described herein does not constitute the “sale” of Personal Data or “targeted advertising” as defined in the Data Privacy Laws, and that as a “Service Provider” or “Processor” the Vendor is prohibited from selling Company Personal Data or retaining, using or disclosing Company Personal Data for a commercial purpose, except as may be permitted by the applicable Data Protection Laws; Company represents that Company Personal Data does not include Personal Data of Data Subjects from the European Economic Area, UK or Switzerland. Company further agrees to provide Vendor with written notice in the event it provides Vendor with such data in order to allow Vendor to implement appropriate safeguards and, whether or not such notice is provided by Company, Company represents and warrants that it has obtained the requisite legal consents required to provide such data to allow Vendor to exercise its rights and process data hereunder. Vendor Processing Requirements For the duration of the Agreement: Vendor will process the Company Personal Data only for purposes of providing, supporting and improving the Services under the Agreement (including to provide insights and other reports), using appropriate technical and organizational security measures. Vendor will require that all personnel of Vendor are bound by confidentiality obligations, which shall comply with Applicable Laws in the context of that individual’s duties, for purposes of Processing the Company Personal Data. Vendor’s compliance with this section may include, without limitation, adopting appropriate confidential information policies governing personnel and subcontractors and/or entering into confidentiality agreements with any applicable employee, agent or contractor, which shall govern the access, use and treatment of Company Personal Data If it intends to engage a Sub-Processor to help it satisfy its obligations in accordance with this DPA, or to delegate all or part of the processing activities to such Sub-Processor, Vendor will: (i) enter into a written agreement with any Sub-Processor that contains Personal Data protection obligations which are no less protective than those of the Vendor in this US DPA; (ii) provide a list of all Sub-Processors; and (iii) remain liable for any breach of this US DPA that is caused by an act, error or omission of its Sub-Processors. If it determines it can no longer meet its obligations under this DPA or Data Processing Laws, Vendor will provide notice to the Company. Upon expiration or termination of the Services or the Agreement, or upon Company’s reasonable request, Vendor will, and will cause its Sub-Processors to, at Company’s option, either return to Company all copies of the Company Personal Data, or delete Company Personal Data from its systems in each case unless Applicable Laws requires the retention of Personal Data by Vendor and/or its Sub-Processors for a particular time or purpose or where Vendor has archived Customer Personal Data on back-up systems, which data will be securely isolated and protected from any further Processing and deleted in accordance with Vendor’s standard data deletion practices. Notwithstanding the foregoing, Vendor may continue to use or Process Company Personal Data that has been aggregated in a manner that does not identify Company, its employees or customers to improve Vendor systems and services. Company hereby authorizes Vendor to aggregate and deidentify the Company Personal Data for such purposes. Company Obligations Company will: (a) determine the purposes and general means of Vendor’s Processing of Company Personal Data (b) ensure that Company and Vendor, acting as a Processor on Company’s behalf, have the right to process Company Personal Data via the Services; and (c) ensure and be solely responsible for the accuracy, quality and legality of Company Personal Data and the means by which Company Personal Data was acquired, including but not limited to, providing adequate notice to, and obtain any necessary consents (to the extent required under Applicable Laws) from Company’s end-users with respect to the Company Personal Data processed via the Services. Rights of Data Subjects With respect to the rights of individuals as provided under applicable Data Protection Laws: Data Subject Requests Received by Vendor: If Vendor receives a Data Subject Request directly from a customer or employee of the Company, Vendor will promptly forward to Company of any such requests. Vendor is not responsible for and will not respond to any such Company Data Subject Request. Assistance to Company to Respond to Data Subject Requests. Upon request by Company, Vendor will provide reasonable assistance to Company in its response to written information requests from Data Subjects, as permitted by Applicable Laws and technical limitations. The Company agrees that in all instances it is responsible for determining that a written information request is a verifiable consumer request and that the requestor is the individual whose Personal Data is being sought. The Company assumes sole responsibility for Personal Data provided in good faith to Vendor in reliance on this Section. With respect to deletion requests, Vendor will delete any relevant Personal Data unless an exemption applies under applicable Data Protection Laws or deleting the Personal Information is not reasonably practicable under the circumstances. After Personal Data is deleted from active systems, it may continue to exist in backups and logs for a period of time until these are overwritten in the ordinary course of business and in accordance with Vendor’s documented data retention and destruction policies. Vendor may charge a reasonable fee for time spent in connection with any assistance or cooperation required by Company. Technical and Organizational Safeguards and Information Security Program Vendor has implemented and maintains a written Information Security Program for the Services and that comply with the safeguards set forth on Schedule2. Company is responsible for independently determining whether Vendor’s Information Security Program meets the Company’s obligations under applicable Data Protection Laws. Company is also responsible for its secure use of the Services, including protecting the security of Company Personal Data in transit to and from the Service (including to securely backup or encrypt any such Company Personal Data). Audits Upon request, Vendor will provide information, assistance and cooperation to Company as may reasonably be required to audit or inspect Vendor’s compliance with this US DPA and with Data Protection Laws. Company may audit Vendor’s compliance with the terms of this US DPA and Data Protection Laws not more than once per year. If a third party is to conduct the audit, Company and the third party will execute a confidentiality agreement before conducting the audit. Audits shall be subject to all applicable confidentiality obligations agreed to by Company and Vendor and shall be conducted in a manner that minimizes any disruption of Vendor’s performance of services and other normal operations, i.e., outside regular business hours. The audit reports are Confidential Information of the parties under the terms of the Agreement. Should the audit reveal confidential information or intellectual property of a third party, any audit must be done in compliance with such third party’s applicable confidentiality or license terms. The information Vendor will provide is limited to permitting examination of the most recent audit reports, certificates and/or extracts prepared by an independent external auditor pursuant to accepted industry certifications, for example a Service Organization Control (“SOC”) report. Customer may use the audit reports only for the purposes of meeting its regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Personal Data Incident Notifications Vendor shall and shall cause its Sub-Processor(s) to maintain Personal Data Incident management policies and procedures and shall notify Company of any Personal Data Incidents without undue delay after becoming aware of a Personal Data Incident affecting Company Personal Data. At Company’s request, Vendor will promptly provide Company with such reasonable assistance as necessary to enable Company to notify competent authorities and/or affected Data Subjects, if Company is required to do so under Data Protection Laws. Vendor may charge a reasonable fee for time spent in connection with any assistance or cooperation required by Company. Company is solely responsible for complying with Personal Data Incident notification requirements applicable to Company and for fulfilling any third-party notification obligations related to any Personal Data Incident. Privacy Representative Each party will designate an individual and an associated email address responsible for corresponding regarding the Processing of Personal Data and any privacy, security, and technical considerations related thereto (including receipt of any Personal Data Incident notifications). For Vendor, in addition to any individual email address, send a copy to dataprivacy [at] usatodayco [dot] com. For Company, Vendor will correspond with the primary business contact designated under the Agreement. Liability Vendor’s liability towards the Company under this DPA is subject to the limitations set forth in the Order and in the LocaliQ terms and conditions. Term This DPA will remain in effect as long as Vendor carries out Processing operations on behalf of the Company or until termination of the Agreement (as all data is returned or deleted pursuant to Section 3(e) above. Governing Law, Jurisdiction and Venue Notwithstanding anything in the Agreement to the contrary, this DPA is governed by the laws of the State of New York, and any action or proceeding related to this DPA must be brought in federal or state court in New York. Conformance with Data Protection Laws Vendor may periodically review and, as necessary, amend this US DPA to update terms as required by any decisions or published guidance of applicable Personal Data protection authorities to ensure continued compliance with applicable Data Protection Laws. Vendor will publish any updates to this DPA in Vendor’s Terms and Conditions and on the dashboard accessible by Company. Conflict If there is any conflict or inconsistency between the terms of this US DPA and the remainder of the Agreement, the terms of this US DPA shall govern. All definitions and any provisions of this US DPA that, by their nature or terms, should survive, shall survive expiration of termination of the Agreement and this US DPA for any reason. SCHEDULE 1 TO US DPA Details of Processing Categories of Personal Data Processed In connection with the Services, Customer may elect to submit Personal Data, the extent of which is determined and controlled by Customer in its sole discretion, and which may include but is not limited to the following categories: Business Contact Information, including address, email, phone numbers, social media contacts, emergency contacts; Unique identification numbers and signatures (for example Social Security number, tax EIN, bank account number, passport or ID card number, driver's license number, IP addresses, unique identifier tracking cookies or similar technology); Financial and insurance information (for example insurance number, bank account name and number, credit card name and number, invoice number, income, type of assurance, payment behavior, creditworthiness); Authentication data (for example user name, password or PIN code, security question, audit trail); Commercial Information (for example history of purchases, subscription information, payment history); Internet activity of Customer’s end users (for example browsing history, search history, reading); Other Personal Data submitted by, sent to, or received by Customer, or its end users, via the Services. In certain instances, including where there is a separate agreement or process in place, Vendor may process Personal Data on Customer’s behalf which may constitute Sensitive Personal Data or protected health information (“PHI”) under applicable federal or state laws. Client represents that, where required, it has obtained consent to collect and process this information on from its customers. This information may include communications directed to Customer in its capacity as a covered entity or regulated business. In addition to the technical and security measures set forth in Schedule 2, LocaliQ will not have direct access to PHI. Such information is accessible only by Customer and is restricted to limited personnel of LocaliQ who have high level IT administrative access only. Customer agrees that this constitutes reasonable safeguarding of such information. Specific Business Purposes of Processing Vendor will Process Personal Data as necessary to provide the Services pursuant to the Agreement as further specified in the Order and as further instructed by Customer in its use of the Services. The specific business purposes include, but are not limited to, providing these Services: Media products (search marketing, targeted display and social ads) Websites SEO Social Media Marketing Live Chat Video Production Listing Management Targeted Email Marketing Branded Content Schedule 2 TO US DPA Technical and Organizational Safeguards and Information Security Program THE FOLLOWING ARE LOCALiQ’s STANDARD REQUIREMENTS FOR PROCESSING PERSONAL DATA. LOCALiQ uses a multi-layered approach to protect Personal Data. We exercise appropriate security controls and measures to manage and protect Personal Data in LocaliQ’s possession from unauthorized or unlawful access, use, alteration, disclosure, distribution, loss, destruction or damage. Our security program is based on a proactive approach and has made investments in people, processes, and technologies. Our security program includes: Use of Security Orchestration Automation & Response (SOAR) technology to automate security monitoring, alerting, and response capabilities Security Information & Event Management (SIEM) platform Automated, continuous vulnerability scanning using threat intelligence to identify high-risk exploitable vulnerabilities Background checks for all personnel Third party pen testing to identify security risks Access Controls and Encryption Multi-Factor Authentication (MFA), VPN access, and strong password controls are required for remote administrative access to systems Access Control Lists (ACLs) prevent unauthorized network access Firewalls are configured to deny all network connections and only allow authorized connections by default Customer provided credentials are securely vaulted, and encrypted at rest (AES-256) and in transit (TLS 1.2 and above) User passwords are hashed following industry best practices and are encrypted at rest Role-based access controls ensure that access is restricted to authorized users Access requests and authorizations are logged to review, investigate, and resolve issues Device and Platform Security Next-Gen Anti-Virus/Anti-Malware (NGAV) with behavioral threat detection Endpoint Detection and Response (EDR) capabilities Mobile Device Management (MDM) controls deployed on mobile devices Cloud Security Posture Management (CSPM) technology for continuous, automated monitoring of cloud infrastructure for misconfigurations and risky configurations Education and Training Mandatory security awareness training for all personnel upon hire, and on an annual basis Communications to all personnel on security tips and how to report suspicious or unusual activity Scheduled email phishing campaigns to help personnel identify suspicious emails Specialized training based on role, such as Security Analyst or Developer Incident Response Up-to-date incident response plans are reviewed and updated at least annually Corporate Cybersecurity Incident Response Team (CIRT) provides 24x7x365 coverage to respond quickly to all types of security events Incident response retainers with leading breach response and law firms if needed Application Protection Change management control and documentation Peer review practices of source code Source code Application Security Testing (SAST) scanning to detect security vulnerabilities in the code base for our most modern apps and services Next-gen Web Application Firewalls (WAF) for additional real-time protection to meet the most stringent PCI DSS requirements as a Level 1 merchant Agile practices incorporating security updates into releases Availability & Disaster Recovery Use of geographic diverse data centers and leading cloud providers (Amazon Web Services & Google Cloud Platform) Data centers use N+1 UPS and power systems and alternate cooling systems Strict access controls are regularly reviewed with activities and incidents monitored on a 24/7 basis with video recordings of physical access points to server rooms Data center network infrastructure to access services is fully redundant and resilient and uses multiple providers, including and leveraging carrier neutral facilities Availability monitoring of services internally and externally with real-time notification of downtime Application performance monitoring to ensure performance standards are met 7/16/2026, 5:06:27 PM | V6.1